SPAN, RSPAN and ERSPAN: Port Mirroring Configuration - 夜莺博客

SPAN, RSPAN and ERSPAN: Port Mirroring Configuration

A switch forwards frames only where they belong, which is excellent for production and terrible for troubleshooting: plug a capture laptop into a spare port and you see nothing. SPAN solves that by copying selected traffic to a dedicated monitoring port, and its two extensions simply extend the distance — RSPAN carries mirrors across a Layer 2 domain, ERSPAN wraps them in GRE so they can cross a routed network. The configuration is short; the failure modes are not obvious.

Local SPAN

SW1(config)# monitor session 1 source interface GigabitEthernet1/0/5 both
SW1(config)# monitor session 1 source interface GigabitEthernet1/0/6 rx
SW1(config)# monitor session 1 destination interface GigabitEthernet1/0/24
SW1# show monitor session 1

Direction keywords matter: rx captures what the connected device sends, tx what the switch sends to it, and both (the default) everything. Prefer the narrower option where you can — the destination port must carry the sum of everything you mirror, and it drops the excess silently when it cannot.

You can mirror a VLAN or a port-channel instead of a port:

SW1(config)# monitor session 2 source vlan 10 both
SW1(config)# monitor session 2 destination interface GigabitEthernet1/0/24

Three rules that bite people

  • The destination port leaves the switching fabric. It learns no MACs, forwards no normal traffic, and by default drops anything the analyser transmits into it. Dedicate it.
  • Oversubscription is silent. Mirroring two full-duplex gigabit ports into a gigabit destination can offer up to 4 Gbps into a 1 Gbps hole; the switch drops the overflow without a counter you will notice.
  • Session counts are a hardware limit — commonly two local sessions on Catalyst access platforms, and they fail quietly when exceeded.

RSPAN: across switches

! on every switch in the path
SW1(config)# vlan 999
SW1(config-vlan)# name RSPAN-MIRROR
SW1(config-vlan)# remote-span

! source switch
SW1(config)# monitor session 3 source interface GigabitEthernet1/0/5 rx
SW1(config)# monitor session 3 destination remote vlan 999

! destination switch (where the analyser is)
SW2(config)# monitor session 3 source remote vlan 999
SW2(config)# monitor session 3 destination interface GigabitEthernet1/0/24

! trunk must carry it
SW1(config-if)# switchport trunk allowed vlan add 999

The remote-span keyword, presence of the VLAN on every transit switch, and inclusion in the trunk allowed list are three independent requirements — miss any one and the mirror is dropped somewhere in the middle with no error on either end. VTP pruning will also happily remove the VLAN and break the capture.

ERSPAN: across routed networks

SW1(config)# monitor session 4 type erspan-source
SW1(config-mon-erspan-src)# source interface GigabitEthernet1/0/5 both
SW1(config-mon-erspan-src)# no shutdown
SW1(config-mon-erspan-src)# destination
SW1(config-mon-erspan-src-dst)# erspan-id 100
SW1(config-mon-erspan-src-dst)# ip address 192.168.99.100
SW1(config-mon-erspan-src-dst)# origin ip address 192.168.10.1

Two things catch everyone: ERSPAN sessions are created administratively down, so without no shutdown the configuration looks perfect and sends nothing; and the GRE plus ERSPAN headers reduce the usable MTU to around 1464 bytes, so full-size frames are truncated or dropped unless the path accommodates them. Also note that ERSPAN encapsulates rather than encrypts — you are shipping copies of production traffic in the clear, so treat that path as sensitive.

Verification and choosing the right tool

SW1# show monitor session all
SW1# show vlan remote-span
SW1# show interfaces GigabitEthernet1/0/1 trunk

Analyser on the same switch → local SPAN. Same Layer 2 domain, different switch → RSPAN. Anywhere routable, or a central capture server → ERSPAN. If the question is "who is using the bandwidth" rather than "what is inside these packets", use flow telemetry instead of mirroring a 10G link.

Related reading: Arista EOS troubleshooting cookbook, SuzieQ network observability, Microbursts and switch buffer sizing.

原文链接:https://pinglabz.com/span-rspan-erspan-configuration